5.199.143.202 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Likely Malicious Host 🟠 70/100

Host and Network Information

  • Tags: Nextray, SSH, TOR, Telnet, VPN, attack, cyber security, ioc, kfsensor, login, malicious, phishing, rdp, scanner, ssh, tsec
  • Known tor exit node
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: blocklist_de, blocklist_de_ssh, blocklist_net_ua, botscout_30d, botscout_7d, dm_tor, et_tor, nixspam, sblam, stopforumspam, stopforumspam_180d, stopforumspam_1d, stopforumspam_30d, stopforumspam_365d, stopforumspam_7d, stopforumspam_90d, tor_exits, tor_exits_1d, tor_exits_30d, tor_exits_7d

  • Known TOR node
  • Country: Germany
  • Network: AS24961 myloc managed it ag
  • Noticed: 50 times
  • Protcols Attacked: SSH
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Malware Detected on Host

Count: 16 5a6ef4bb96efacaa4db232c1d28c37e3b5ec0e471b948ed2b55770db5e820e24 4d3b369698cd8b6fc6bd6c5c6439929ab14f65a3ce0cd2a557b4e31b12e4295c 31e336d15f3414e6bae7056b612b3529b0af5c6656f93f9c3d51312a3ce8935c 7b0dad1c77e7e11c5e9fc857bfac196a309d6935b18bdbf4835a359ebd32f186 e6aca25a484efc2f6c65d72999ad040b8258e7633553533c3bd41770937008c4 7cf34eadb163afa46e8936bc8a37c38d51a646079d39897397ab6bd3fd527f9a 91e0c268211f9e8d9a28e6d8526188360563e1e57739156c07d4ac3e8617bb23 a7e484d7cdbcb39538cd203c269d39b15d59f1703cf73429ca67128bb66c0a00 c3bee7ed9d81f9d851ca45f952261ba1b486c74b9dd388742becfeefd7e88093 4b9c21d9da89c399832f18b4c9a2b4a32788937070b5494404a6e5b3d601a74b

Open Ports Detected

80 8080 88 8888

Map

Whois Information

  • inetnum: 5.199.143.0 - 5.199.143.255
  • netname: MYLOC-DE-DUS2-DEDICATED-SERVER
  • descr: webtropia dedicated Server by http://www.webtropia.com
  • descr: myLoc managed IT AG
  • country: DE
  • admin-c: MOPS-RIPE
  • tech-c: MOPS-RIPE
  • status: ASSIGNED PA
  • mnt-by: MYLOC-MNT
  • created: 2013-01-02T06:24:15Z
  • last-modified: 2016-04-13T10:07:17Z
  • role: myLoc NOC
  • address: myLoc managed IT AG
  • address: Network Operations & Services
  • address: Am Gatherhof 44
  • address: 40472 Duesseldorf DE
  • admin-c: PHAN
  • tech-c: PHAN
  • tech-c: DDO
  • tech-c: JOH
  • tech-c: NIL
  • tech-c: STH
  • tech-c: KT3550-RIPE
  • nic-hdl: MOPS-RIPE
  • abuse-mailbox: [email protected]
  • mnt-by: MYLOC-MNT
  • created: 2013-02-11T16:38:10Z
  • last-modified: 2022-07-08T14:48:44Z
  • route: 5.199.128.0/20
  • descr: myLoc managed IT AG
  • origin: AS24961
  • mnt-by: MYLOC-MNT
  • created: 2012-08-29T12:29:55Z
  • last-modified: 2017-02-07T16:39:12Z

Links to attack logs

bruteforce-ip-list-2021-05-12